Written by 1:18 pm Blog

UK, US and Netherlands warn over Iranian state spyware campaign  

Arpad Nagy-Bagoly – stock.adobe. Cyber attackers linked to Iran’s Ministry of Intelligence an…
UK, US and Netherlands warn over Iranian state spyware campaign   

Arpad Nagy-Bagoly – stock.adobe.

Cyber attackers linked to Iran’s Ministry of Intelligence and Security are targeting opponents and opposition groups with Windows spyware

 

By

Published: 15 Sep 2026 18:18

Iranian state hackers are targeting dissidents, activists and journalists with spyware capable of tracking their movements, GCHQ’s National Cyber Security Centre (NCSC) has warned.

The Iranian spearphishing campaign has targeted people around the world, according to alerts from the UK, the Netherlands and the US.

Iranian cyber attackers have used social engineering techniques to persuade people to download files containing hidden malware that infects Windows-based devices.

The malware, identified as Chosen Brick, has been used to target individuals in the UK, the US and the Netherlands since at least 2025.

Personal information leaked

Once deployed, the malware enables Iranian state cyber attackers to collect information about a target’s contacts, emails and social media messages.

The personal details of victims have been published on pro-Iranian leak sites, potentially putting the personal safety of victims at risk.

According to UK intelligence assessments, Iran is almost certainly using cyber attacks to repress individuals seen as a threat to the regime.

In some cases, Iranian intelligence services have plotted to kidnap or conduct lethal operations against people they perceive as a threat outside of Iran.

Social engineering attack

Attackers contact victims through social media platforms and messaging services, such as WhatsApp, Telegram and Instagram, to build a rapport before tricking them into downloading the malware.

The attackers have deep knowledge of the target and often purport to be an individual known to them or pose as technical support from the social media platform.

They use their relationship with the victim to persuade them to download what appear to be legitimate files.

Malicious files have been disguised as artificial intelligence video-generating software Pictory, Norton Antivirus, messaging app Telegram, or password management tool KeePass. In other cases, malicious files have been disguised as MRI scan results.

The attackers often initiate contact using their target’s work device, but if that fails or is considered too risky, they will attempt to ask the target to open files on their own device to bypass corporate security, according to the NCSC’s advisory.

Once downloaded, the malware connects to the Telegram messaging app to receive instructions. Each compromised device connects to a different Telegram Bot ID to reduce the risk of detection.

The malware has the capability to download additional malware files to the infected machine, but has so far not been observed trying to spread to other machines.

It can be tasked with capturing the content of screens, enabling a microphone to capture audio, or capturing Telegram and WhatsApp data from browsers.

It can also delete files, steal the content of emails and wipe the infected computer system.

Ruthless digital surveillance

Paul Chichester, NCSC director of operations, said the UK would continue to call out malicious cyber activity by the Iranian state.

“The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices,” he added.

Advice on how to detect the Iranian malware can be found here and here.

Read more on Hackers and cybercrime prevention

Article Source

Close